Skip to content
ThreatSTOP for AWS Blog

Turn Active Directory into a security control point.

Today's attacks increasingly use DNS to reach command-and-control infrastructure, to encrypt or exfiltrate data, and to spread. Active Directory is already answering those queries. ThreatSTOP turns your Windows DNS servers into protective DNS enforcement points with a cloud service, so dangerous and unwanted queries are blocked before the connection is made.

No new hardware, no agents.

Active Directory is everywhere, and ThreatSTOP can turn the AD servers you already run into protective DNS enforcement points with a simple cloud service. Four steps to get there.

01
Build your policy
Create security policies in the ThreatSTOP portal to protect against specific threat types, geographic locations, and your own domains or wildcards.
02
Turn it on in Windows DNS
Configure your Windows Server 2016 or later DNS to run the ThreatSTOP service. No new hardware, no agents.
03
Policies stay current
Policies update continuously with live threat intelligence curated from global authoritative sources and ThreatSTOP's research team.
04
See the detail
View detailed information about threats blocked on your network and identify infected client machines using advanced web-based reporting.

What the platform does for you.

Intelligence collection
Broad, curated coverage
Hundreds of threat intelligence feeds, curated by people and machines, delivering broad coverage of malicious IP addresses and domains.
Policy customization
Tune it to your network
Fully customizable policies in selectable categories, plus your own custom block and allow lists.
Device integration
Push it everywhere
Automated policy updates for NGFW, DNS, router, switch, IDP, WAF, SIEM, and more.
Advanced reporting
Know what was stopped
View and analyze blocked threats, identify affected client devices, and schedule custom email reports and alerts.

What you get out of it.

Save time
Stop managing lists by hand
Automate and outsource essential 24/7 security policy updates, get rich reports in our portal or your SIEM, rapidly identify infected hosts, and schedule the email reports and alerts you want.
Save money
Get more from what you own
Add powerful security to existing devices, reduce endpoint infections, take load off your other security layers, and eliminate unwanted bandwidth usage.
Be more secure
Close the paths attackers use
Block connection attempts to criminal infrastructure on all ports and protocols, with continuous automatic policy updates and policies you tune to your own security posture.

Dig into the detail.

Learn more about our protective DNS solution for Windows Server and Active Directory.

Protective DNS on the servers you already run.

Start a trial on your own Active Directory environment and see what it blocks.